2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47257 | HIGH | 7.5 | 0.5% | Nov 26, 2024 | Florent Thiéry has found that selected Axis devices were vulnerable to handling certain ethernet frames which could lead... |
| CVE-2024-36254 | HIGH | 7.5 | 0.7% | Nov 26, 2024 | Out-of-bounds read vulnerability exists in Sharp Corporation and Toshiba Tec Corporation multiple MFPs (multifunction pr... |
| CVE-2024-36251 | HIGH | 7.5 | 3.5% | Nov 26, 2024 | The web interface of the affected devices process some crafted HTTP requests improperly, leading to a device crash. More... |
| CVE-2024-36249 | HIGH | 7.4 | 0.5% | Nov 26, 2024 | Cross-site scripting vulnerability exists in Sharp Corporation and Toshiba Tech Corporation multiple MFPs (multifunction... |
| CVE-2024-33605 | HIGH | 7.5 | 6.2% | Nov 26, 2024 | Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for th... |
| CVE-2024-10781 | HIGH | 7.5 | 3.8% | Nov 26, 2024 | The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugi... |
| CVE-2024-10570 | HIGH | 7.5 | 0.5% | Nov 26, 2024 | The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized SQL Injection due to an auth... |
| CVE-2024-10542 | HIGH | 7.5 | 15.2% | Nov 26, 2024 | The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugi... |
| CVE-2024-49597 | HIGH | 7.2 | 0.6% | Nov 26, 2024 | Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Authentication Atte... |
| CVE-2024-10729 | HIGH | 8.8 | 0.5% | Nov 26, 2024 | The Booking & Appointment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data... |
| CVE-2024-52899 | HIGH | 8.8 | 0.8% | Nov 26, 2024 | IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL para... |
| CVE-2024-53843 | HIGH | 8.1 | 0.5% | Nov 26, 2024 | @dapperduckling/keycloak-connector-server is an opinionated series of libraries for Node.js applications and frontend cl... |
| CVE-2024-11674 | HIGH | 8.8 | 0.6% | Nov 26, 2024 | A vulnerability, which was classified as critical, was found in CodeAstro Hospital Management System 1.0. Affected is an... |
| CVE-2024-53554 | HIGH | 8 | 0.7% | Nov 25, 2024 | A Client-Side Template Injection (CSTI) vulnerability in the component /project/new/scrum of Taiga v 8.6.1 allows remote... |
| CVE-2024-53099 | HIGH | 7.1 | 0.2% | Nov 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: bpf: Check validity of link->type in bpf_link_show_... |
| CVE-2024-53098 | HIGH | 7.8 | 0.2% | Nov 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/ufence: Prefetch ufence addr to catch bogus ... |
| CVE-2024-53096 | HIGH | 7.8 | 0.3% | Nov 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: mm: resolve faulty mmap_region() error path behavio... |
| CVE-2024-53268 | HIGH | 8.8 | 0.7% | Nov 25, 2024 | Joplin is an open source, privacy-focused note taking app with sync capabilities for Windows, macOS, Linux, Android and ... |
| CVE-2024-52811 | HIGH | 8.2 | 0.8% | Nov 25, 2024 | The ngtcp2 project is an effort to implement IETF QUIC protocol in C. In affected versions acks are not validated before... |
| CVE-2024-8272 | HIGH | 7.8 | 0.2% | Nov 25, 2024 | The com.uaudio.bsd.helper service, responsible for handling privileged operations, fails to implement critical client va... |
| CVE-2024-7915 | HIGH | 7.8 | 0.2% | Nov 25, 2024 | The application Sensei Mac Cleaner contains a local privilege escalation vulnerability, allowing an attacker to perform ... |
| CVE-2024-45756 | HIGH | 7.2 | 0.5% | Nov 25, 2024 | An issue was discovered in Centreon centreon-open-tickets 24.10.x before 24.10.0, 24.04.x before 24.04.2, 23.10.x before... |
| CVE-2024-45755 | HIGH | 7.2 | 0.5% | Nov 25, 2024 | An issue was discovered in Centreon centreon-dsm-server 24.10.x before 24.10.0, 24.04.x before 24.04.3, 23.10.x before 2... |
| CVE-2024-27134 | HIGH | 7 | 0.1% | Nov 25, 2024 | Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be... |
| CVE-2024-11498 | HIGH | 7.5 | 0.6% | Nov 25, 2024 | There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now